CVE-2009-4631
published 2010-02-10CVE-2009-4631: Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a…
PriorityP336critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.10%
91.5th percentile
Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted VP3 file that triggers an out-of-bounds read and possibly memory corruption.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 4:0.5+svn20090706-3 (bookworm) | ffmpeg 4:0.5+svn20090706-3 (bookworm) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 4:0.5+svn20090706-3 | 4:0.5+svn20090706-3 |
| ffmpeg | ffmpeg | >= 0 < 4:0.5+svn20090706-3 | 4:0.5+svn20090706-3 |
| ffmpeg | ffmpeg | >= 0 < 4:0.5+svn20090706-3 | 4:0.5+svn20090706-3 |
| ffmpeg | ffmpeg | >= 0 < 4:0.5+svn20090706-3 | 4:0.5+svn20090706-3 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x344-wx2q-g6rh: Off-by-one error in the VP3 decoder (vp3
ghsa_unreviewed·2022-05-02
CVE-2009-4631 [HIGH] GHSA-x344-wx2q-g6rh: Off-by-one error in the VP3 decoder (vp3
Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted VP3 file that triggers an out-of-bounds read and possibly memory corruption.
OSV
CVE-2009-4631: Off-by-one error in the VP3 decoder (vp3
osv·2010-02-10·CVSS 9.3
CVE-2009-4631 [CRITICAL] CVE-2009-4631: Off-by-one error in the VP3 decoder (vp3
Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted VP3 file that triggers an out-of-bounds read and possibly memory corruption.
Debian
CVE-2009-4631: ffmpeg - Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attacker...
vendor_debian·2009·CVSS 9.3
CVE-2009-4631 [CRITICAL] CVE-2009-4631: ffmpeg - Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attacker...
Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted VP3 file that triggers an out-of-bounds read and possibly memory corruption.
Scope: local
bookworm: resolved (fixed in 4:0.5+svn20090706-3)
bullseye: resolved (fixed in 4:0.5+svn20090706-3)
forky: resolved (fixed in 4:0.5+svn20090706-3)
sid: resolved (fixed in 4:0.5+svn20090706-3)
trixie: resolved (fixed in 4:0.5+svn20090706-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://scarybeastsecurity.blogspot.com/2009/09/patching-ffmpeg-into-shape.htmlhttp://secunia.com/advisories/36805http://secunia.com/advisories/38643http://www.debian.org/security/2010/dsa-2000http://www.securityfocus.com/bid/36465https://roundup.ffmpeg.org/roundup/ffmpeg/issue1240https://roundup.ffmpeg.org/roundup/ffmpeg/issue1483http://scarybeastsecurity.blogspot.com/2009/09/patching-ffmpeg-into-shape.htmlhttp://secunia.com/advisories/36805http://secunia.com/advisories/38643http://www.debian.org/security/2010/dsa-2000http://www.securityfocus.com/bid/36465https://roundup.ffmpeg.org/roundup/ffmpeg/issue1240https://roundup.ffmpeg.org/roundup/ffmpeg/issue1483
2010-02-10
Published